URLhaus Database

You are currently viewing the URLhaus database entry for http://87.249.142.126:60800/AV.scr which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3655825
URL: http://87.249.142.126:60800/AV.scr
URL Status:flame Online (spreading malware for 10 months, 0 days, 15 hours, 26 minutes)
Host: 87.249.142.126
Date added:2025-10-04 05:09:32 UTC
Threat:Malware download Malware download
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-10-04 05:10:28 UTC to abuse-ttnet{at}ttnet[dot]cz)
Tags:CoinMiner

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-31AV.screxe b5c43ec474a2e7f4196b13bae7a71dd2c0032313d3663a3807da4d5fc7947a80n/a 
2026-06-25AV.screxe 4680aaa2a2a476ef246b4db37b7f44ef2c9c673876033d83fca02cb9e33db10an/a 
2026-06-19AV.screxe d89d2213c4d5581549704e57122658e8b0ac6e27d26107cb6a1a3ada74753b66n/a 
2026-05-08AV.screxe 007b0513a828eadee25ad16bf6e8eeacafe621e0adf4f6c6d03bd35bc4047e31n/a 
2026-05-08AV.screxe a23b9f2254554d694fd9538cfc85dd72b6d9dc8084c3a48fdbafaa043aa87f7bn/a 
2026-04-25AV.screxe 163ade9d672ac8f4b1dabb7bbf173c8191ec47a7bab75bef9664020c028d708fn/a CoinMiner
2026-01-12AV.screxe 12953b8ef0d027787ac6dbe477ea58ab3535d3e85558a10b9936bf3914973874n/a 
2026-01-10AV.screxe 20d0cc1cf16ed908eaeb5bf617b213d28619bb1810577804ec30ebf402c47ec4n/a 
2026-01-08AV.screxe 778efe083950ba83267aa098522c0a3040dedd9eebca437470850ff0ad3e6444n/a 
2026-01-05AV.screxe 014cd33e08e15c6fcfb383e59764c9b054ebd149487c10397784acc8dd2a24f8n/a 
2026-01-03AV.screxe fd998620bc343d829d711d5b62896bec1f365d7bf7a6b6de92a5e61959477113n/a 
2025-10-04AV.screxe 5d9fe2735d4399d98e6e6a792b1feb26d6f2d9a5d77944ecacb4b4837e5e5fcaVirustotal results 81.69%CoinMiner